CVE-2017-2834 is a code execution vulnerability affecting FreeRDP 2.0.0-beta1+android11 and various Debian Linux distributions. A specially crafted server response can trigger an out-of-bounds write during authentication, leading to an exploitable condition. With a CVSS score of 7.0 (High), this vulnerability can be exploited by an attacker compromising the server or via a man-in-the-middle attack, potentially resulting in limited confidentiality, integrity, and high availability impact. There is no evidence of active exploitation, and no public exploit code is available, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:freerdp:freerdp:2.0.0:beta1:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.